SB20260720443 - Improper access control in Linux kernel ntfs3
Published: July 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-63833)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper access control in the ntfs3 xattr handler when handling direct userspace writes to reserved $LX* extended attributes. A local user can set crafted $LXUID, $LXGID, $LXMOD, or $LXDEV values on a file they own to escalate privileges.
Exploitation requires a writable ntfs3 mount and relies on inode reload of WSL permission metadata into inode ownership and mode fields.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/293a84fa40b3a1b3471c0545722724bc10973f76
- https://git.kernel.org/stable/c/2c3cd6da4a14380ef79e34bd9dff7caf46687477
- https://git.kernel.org/stable/c/5b08dccecf825cbf905f348bc6ccb497507e28e2
- https://git.kernel.org/stable/c/5e658b9245a52d838ef93729a7bc07de8e19deb7
- https://git.kernel.org/stable/c/e574af95234afc3c725988bbc1fdeb46b9f386a4
- https://git.kernel.org/stable/c/e8852ae29868e449fdb47eebc28f35fb80741a5f
- https://git.kernel.org/stable/c/f8d420949b335a4b51d06ab276beee6b8dfdc909